New issue
Advanced search Search tips

Issue 645340 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 642664
Owner: ----
Closed: Sep 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: google chrome browser (makes million http site at risk)

Reported by eveaustr...@gmail.com, Sep 9 2016

Issue description

Hello i found a bug in googlechrome browser by accident at first i thought this is a http bug. but when i reported this to many site @hackerone.com they told me their site is not the one that cause this its the browser.. 

This attack is kinday tricky because millions of http website is at risk..

Attack type: reflected XSS
vulnerable sites: http site that has the url like this "site.com"
not vulnerable: https://site.com, www.site.com etc


how to perform this attack first check a target like this example:

site.com
put the payload javascript:alert(0). front of the site
it will look like this javascript:alert(0).site.com
the tricky part is you cannot use this as a copy paste attack instead you need to manual type the javascript payload in front of the url but first you need to load the site first before you inject the payload..


actually i was advise to report it because millions of http site is at risk because of this... 


hope to hear from your side


for POC kindly check this youtube video (this is the one i reported to uber because they launched a bug bounty program)

https://www.youtube.com/watch?v=sE_EvyRD7kA


best regards,
evez


 
Mergedinto: 642664
Status: Duplicate (was: Unconfirmed)
Hi, this is not a security bug, as it requires the victim to type the XSS payload into their URL bar. For more details, see https://bugs.chromium.org/p/chromium/issues/detail?id=642664#c1
Project Member

Comment 2 by sheriffbot@chromium.org, Dec 16 2016

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment